Microsoft

Windows 11 25h2

1189 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 19.8%
  • Veröffentlicht 13.01.2026 17:57:00
  • Zuletzt bearbeitet 30.07.2026 21:17:06

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • EPSS 0.47%
  • Veröffentlicht 13.01.2026 17:56:59
  • Zuletzt bearbeitet 30.07.2026 21:17:06

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • EPSS 0.3%
  • Veröffentlicht 13.01.2026 17:56:58
  • Zuletzt bearbeitet 30.07.2026 21:17:05

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • EPSS 1.39%
  • Veröffentlicht 13.01.2026 17:56:58
  • Zuletzt bearbeitet 30.07.2026 21:17:06

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • EPSS 0.39%
  • Veröffentlicht 13.01.2026 17:56:57
  • Zuletzt bearbeitet 30.07.2026 21:17:05

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • EPSS 0.3%
  • Veröffentlicht 13.01.2026 17:56:57
  • Zuletzt bearbeitet 30.07.2026 21:17:05

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • EPSS 0.64%
  • Veröffentlicht 13.01.2026 17:56:56
  • Zuletzt bearbeitet 30.07.2026 21:17:05

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

  • EPSS 0.3%
  • Veröffentlicht 13.01.2026 17:56:55
  • Zuletzt bearbeitet 30.07.2026 21:17:04

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • EPSS 0.32%
  • Veröffentlicht 13.01.2026 17:56:54
  • Zuletzt bearbeitet 30.07.2026 21:17:03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.

  • EPSS 1.09%
  • Veröffentlicht 13.01.2026 17:56:54
  • Zuletzt bearbeitet 30.07.2026 21:17:03

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.